GlobalSign: Failure to revoke noncompliant ICA within 7 days
This case is an incident report from GlobalSign about 25 intermediate (ICA) certificates that were not revoked within the BR time period. GlobalSign stated it became aware of the issue after reviewing items in its CCADB task “Check failed Audit Letter Validation (ALV) results” and found 30 ICA certificates missing, with an intention to revoke 25 of them. GlobalSign said these 25 intermediate certificates were not intended to issue SSL/TLS certificates and that it had stopped issuing intermediate certificates without specific EKUs by the end of 2018. GlobalSign reported that it requested the 25 identified ICAs to be added to oneCRL and planned a customer migration exercise prior to revocation due to extensive customer usage. GlobalSign also described remediation initiatives, including a hierarchy hygiene exercise and rotation of TLS ICA to limit the number of leafs and enable more timely revocation. Later, GlobalSign reported generating “next generation” roots that separate different certificate use cases and asked whether the ticket could be closed; Fastly responded that questions were answered and remediation was complete. The bug is marked RESOLVED with resolution FIXED.
- GlobalSign reviewed CCADB “Check failed Audit Letter Validation (ALV) results” and identified ICA certificates missing from audit reports.
- GlobalSign opened the incident report describing non-revocation of 25 intermediate certificates within the BR time period.
- GlobalSign outlined remediation initiatives including hierarchy hygiene and TLS ICA rotation.
- GlobalSign generated next-generation roots separating certificate use cases under different roots.
- Fastly confirmed that questions were answered and remediation was complete.
- GlobalSign nv-sa — GlobalSign reported an incident involving 25 intermediate certificates not revoked within the BR time period and stated it planned to revoke them, with revocation details referenced in Bug 1591005.
- Community commenter — Ryan Sleevi questioned GlobalSign’s remediation steps and requested valuable information about how GlobalSign would ensure timely revocation in the future.
- GlobalSign nv-sa — GlobalSign described short-, mid-, and long-term initiatives (hierarchy hygiene and TLS ICA rotation) to address revocation timing and related PKI administration issues.
- GlobalSign nv-sa — GlobalSign stated it generated next-generation roots separating certificate use cases and asked whether the ticket could be closed.
- Fastly representative — Fastly replied that it appeared all questions were answered and remediation was complete.